Doc #55624 [Csd]: session_set_save_handler should mention locking
| From: | yohgaki@php.net | Date: | Mon, 17 Oct 2016 18:26:32 +0000 |
| Subject: | Doc #55624 [Csd]: session_set_save_handler should mention locking | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-14024@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55624&edit=1
ID: 55624
Updated by: yohgaki@php.net
Reported by: tyrael@php.net
Summary: session_set_save_handler should mention locking
Status: Closed
Type: Documentation Problem
Package: Session related
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
BTW, I'm going to fix session save handler's mess soon, object interface interface
especially.
IIRC, I've written full procedural save handler implementation many years ago that includes
exclusive locks in the manual that includes precise return data types for each handler. This was
removed from the manual somehow, and replaced by OO only description which lacks many aspects. I
might have written this in somewhere else. It's very long time ago.
Current manual page lacks create_sid, validate_sid, update_timestamp handler description, even if
validate_sid handler implementation is mandatory absolutely. Since I implemented validate_sid,
I'm certain that I've written manual for this. The manual page is gone also.
I shall write complete manual page when save handler mess is corrected.
Previous Comments:
------------------------------------------------------------------------
[2016-10-17 12:01:16] narf at devilix dot net
That may be enough on the new section you've created, but this issue is explicitly about the
examples on https://secure.php.net/session_set_save_handler
Many users use that as a reference or just straight copy-paste from there, and there are zero
mentions of locking on that page.
------------------------------------------------------------------------
[2016-10-17 11:56:05] yohgaki@php.net
"Session data is locked to avoid races by default. Locking is mandatory to keep session data
consistent across requests."
Isn't this enough?
I agree this isn't enough for beginners, though.
------------------------------------------------------------------------
[2016-10-17 11:40:46] narf at devilix dot net
Why is this closed with a link to http://php.net/manual/en/features.session.security.management.php#features.session.security.management.session-locking
?
The issue was about adding flock() calls to the examples on session_set_save_handler() ([1]) and
warning them against the dangers of NOT using locks.
It was NOT about scaring users away from locking with talks about DoS attacks.
* [1] http://php.net/manual/en/function.session-set-save-handler.php
------------------------------------------------------------------------
[2016-10-17 11:21:21] yohgaki@php.net
This is documented in session security section now.
http://php.net/manual/en/features.session.security.management.php#features.session.security.management.session-locking
------------------------------------------------------------------------
[2013-01-16 19:26:32] googleguy@php.net
Related To: Bug #63278
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=55624
--
Edit this bug report at https://bugs.php.net/bug.php?id=55624&edit=1